Remote (Country)

Tines is hiring a Senior GRC Analyst

About the Role

Tines is looking for a Senior GRC Analyst to strengthen our compliance strategy and execution during a pivotal growth phase. Reporting directly to the Head of IT Operations & Information Security, you will play a critical role in our FedRAMP program while maintaining our existing SOC 2 compliance.

What You'll Do

  • Assist our FedRAMP certification program, including gap analysis, remediation planning, documentation development, and coordination with 3PAO assessors
  • Support continuous compliance with SOC 2 requirements, including evidence collection, control testing, and audit coordination
  • Establish and manage a comprehensive vendor risk assessment program, evaluating security controls and compliance posture before acquisition
  • Conduct thorough risk analyses for systems, processes, and third-party applications, implementing appropriate controls to mitigate identified risks
  • Leverage Tines automation capabilities to streamline compliance processes, evidence collection, and reporting
  • Respond to customer security inquiries, questionnaires, and audit requests, maintaining our Trust Center with up-to-date documentation
  • Review, update, and develop security policies and procedures aligned with regulatory requirements and industry best practices
  • Partner with engineering, product, legal, and leadership teams to embed compliance requirements into organizational processes
  • Collaborate closely with the legal team to review contracts for security and compliance requirements, ensure appropriate security provisions are included, identify potential compliance risks, and recommend mitigating controls
  • Help develop standardized security language for various contract types
  • Stay current with evolving compliance standards and regulatory requirements relevant to our business and customers

What We're Looking For

  • 8+ years of experience in IT compliance, security, or risk management
  • Demonstrated experience with FedRAMP certification processes and requirements
  • Hands-on experience implementing or maintaining ISO 27001 compliance
  • Strong knowledge of SOC 2 compliance frameworks and audit processes
  • Experience conducting vendor security assessments and risk analyses
  • Excellent understanding of information security principles, controls, and best practices
  • Strong project management skills with ability to manage multiple compliance initiatives simultaneously
  • Exceptional communication skills for translating technical requirements to non-technical stakeholders

Nice to Have

  • Industry certifications such as CISSP, CISA, or CISM
  • Experience with compliance automation tools and techniques
  • Knowledge of cloud security principles and controls (AWS, Azure, GCP)
  • Experience reviewing contracts for security and compliance requirements
  • Experience in SaaS or technology companies
  • Familiarity with privacy regulations (GDPR, CCPA)
  • Experience working in remote-first environments

Team & Environment

You will report directly to the Head of IT Operations & Information Security.

Work Mode

This role operates in local-country work mode, based in the United States.

Tines provides equal employment opportunities to all employees and applicants for employment without regard to sex, race, colour, ethnic or social origin, genetic features, language, religion or belief, political or any other opinion, membership of a national minority, property, birth, disability, age or sexual orientation.

Required Skills
GRCRisk ManagementComplianceSecurity FrameworksAuditPolicy DevelopmentVendor Risk ManagementSecurity TrainingIncident ResponseCloud SecurityData Privacy
Visa expiring soon?

Extend or switch without leaving Thailand

Running out of time on your current visa? SVBL identifies your best option — extension, category switch, or long-term visa — and handles the entire process.

Visa extensions & category switches
LTR & DTV visa applications
90-day reporting managed
Overstay prevention
Check your options
Prevent overstay issues
About company
Tines

Founded in 2018 with co-headquarters in Dublin and Boston, Tines powers some of the world's most important workflows. Our intelligent workflow platform applies AI, automation, and integration with human ingenuity to drive real business results. Tines serves a diverse range of customers, from startups to public companies, including Canva, Databricks, Elastic, Kayak, Intercom, and McKesson. As an integrator across the entire tech stack, Tines is vendor-agnostic integrating with any API-enabled service.

Visit website
Job Details
Category security
Posted 7 months ago